SUSE-SU-2026:2830-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 09 Jul 2026, 18:42
Last modified:10 Jul 2026, 10:00

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2026, 18:42
Published
Vulnerability first disclosed
10 Jul 2026, 10:00
Last Modified
Vulnerability information updated

Description

Security update for warewulf4 This update for warewulf4 fixes the following issues: Update to v4.7.0. Security issues fixed: - CVE-2025-69725: incorrect input validation in the `RedirectSlashes` function can lead to an open redirect (bsc#1258511). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` can lead to a denial of service (bsc#1265653). - CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483). Other updates and bugfixes: - Add correct flag `--update-overlays` fix (bsc#1268790). - v4.7.0: * New `wwctl` unset command * Refactored server routes (URLs) * New `/files/` route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - v4.6.5: * New wwctl overlay info command * Fixed `wwctl` image import `--update` option * Cross-arch support for `wwclient` * Improved IPv6 support * Improved support for bonded interfaces * Renamed `debian.interfaces` overlay to `ifupdown` * New `systemd-networkd` overlay * `warewulf-dracut` fixes, including `provision-to-disk` fixes - Remove `slurm-overlay` package. - Fix `wwctl` image import `--update` option (bsc#1254470).

Affected Systems

  • susewarewulf4&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS

    < 4.7.0-150500.6.42.1

  • susewarewulf4&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS

    < 4.7.0-150500.6.42.1

  • susewarewulf4&distro=SUSE Linux Enterprise Module for HPC 15 SP7

    < 4.7.0-150500.6.42.1

  • susewarewulf4&distro=SUSE Linux Enterprise Server 15 SP6-LTSS

    < 4.7.0-150500.6.42.1

References (11)